Privacy Policy

AI Meal Scanner Privacy Policy

Effective date: 14 July 2026

AI Meal Scanner is provided by Jojo Apps, Ganzenberg 63, 9220 Moerzeke, Belgium (“Jojo Apps,” “we,” “us,” or “our”).

This Privacy Policy explains how the Android and iOS versions of AI Meal Scanner access, collect, use, disclose, retain, and delete information.

AI Meal Scanner does not require users to create a Jojo Apps account.

1. Information we process

1.1 Meal photographs and AI analysis

When you take or select a photograph for scanning, AI Meal Scanner sends a compressed copy of that photograph to Google Firebase AI Logic and the Vertex AI Gemini API.

The app also sends the language configured on your device so that the analysis can be returned in the appropriate language.

This processing is necessary to:

  • Identify foods shown in the photograph;
  • Generate estimated nutritional information;
  • Return the analysis to the app; and
  • Provide the app’s core meal-scanning functionality.

Google processes this information on our behalf as a service provider.

Firebase AI Logic does not store meal photographs in Firebase Storage. However, the Vertex AI service must process the photograph to respond to the request. Vertex AI may cache input and output data in memory for up to 24 hours. Requests identified as potentially abusive may be logged for security and abuse-monitoring purposes for up to 30 days.

If AI monitoring is enabled for our Firebase project, request and response information may also be stored in Google Cloud logging. The default retention period for these logs is 30 days unless another period is configured.

Google states that customer data submitted to Vertex AI is not used to train or fine-tune AI or machine-learning models without the customer’s permission or instruction.

Please do not submit photographs containing identifiable people, documents, payment details, medical documents, or other sensitive information unrelated to meal scanning.

1.2 Meal history stored on your device

After a scan is completed, the app stores the following information locally on your device:

  • The meal photograph;
  • The date and time of the scan;
  • Identified food names;
  • Food-recognition confidence values; and
  • Estimated calories, protein, carbohydrates, and fat.

Jojo Apps does not upload this meal history to Firebase Storage or maintain it in a Jojo Apps user account.

The locally stored meal history remains on your device until you:

  • Delete an individual scan;
  • Clear the app’s data through your device settings;
  • Delete all meal data using an available in-app deletion option; or
  • Uninstall the app.

Depending on your operating-system and device-backup settings, local app information may be included in a backup managed by Google, Apple, or the device manufacturer. Jojo Apps does not control those backups. Deleting the app may not immediately delete a copy already contained in such a backup.

1.3 Camera and photo-library access

AI Meal Scanner requests access to the camera so that you can photograph a meal.

You may also choose an existing photograph using the system photo picker. The app receives only the photograph you select through the picker. It does not scan or upload your entire photo library.

Camera and photo access is used only to provide meal-scanning functionality.

1.4 Analytics

We use Google Analytics for Firebase to understand how the app is used and to improve its functionality and reliability.

Depending on the device and platform, Analytics may process:

  • A pseudonymous app-instance identifier;
  • App launches and sessions;
  • Screen and feature interactions;
  • Purchase-related events;
  • Device type and operating-system information;
  • App version and configuration;
  • General geographic information derived from the network connection; and
  • Other usage statistics.

We do not intentionally send meal photographs, identified food names, or nutritional results to Firebase Analytics.

User-level and event-level Analytics data is retained for no longer than 14 months. Certain aggregated reports that no longer directly identify a particular app installation may be retained for longer.

1.5 Crash reporting and diagnostics

We use Firebase Crashlytics to identify crashes, diagnose technical problems, and improve the stability of the app.

Crash reports may include:

  • Crash traces and technical logs;
  • The date and time of a crash;
  • App version and bundle or package identifier;
  • Device model;
  • Operating-system name and version;
  • Available memory and storage information;
  • Whether the device is modified, rooted, or jailbroken;
  • Firebase installation and Crashlytics identifiers; and
  • App interactions immediately preceding a crash.

We do not intentionally attach meal photographs or meal analysis results to crash reports.

Firebase Crashlytics normally retains crash information and associated identifiers for 90 days before beginning removal from active and backup systems.

1.6 App security and fraud prevention

We use Firebase App Check to protect the AI service against unauthorized access, automated abuse, and fraud.

Firebase App Check uses:

  • Google Play Integrity on Android; and
  • Apple App Attest on iOS.

These services may process app-attestation information, installation identifiers, device integrity signals, and short-lived security tokens.

Firebase App Check does not retain the underlying attestation material. App Check tokens are short-lived and cannot have a validity period longer than seven days. When replay protection is used, previously used tokens may be retained for up to 30 days.

1.7 Advertising on Android

The free Android version of AI Meal Scanner displays advertisements through Google AdMob.

The Google Mobile Ads SDK may automatically collect or process:

  • The device’s IP address;
  • Approximate location derived from the IP address;
  • Android advertising ID;
  • App-set ID and other device or account identifiers;
  • App launches, taps, ad impressions, video views, and other interactions;
  • Diagnostic and performance information; and
  • Information used to detect advertising fraud and abuse.

Google and participating advertising partners may use this information to:

  • Select and display advertisements;
  • Personalize advertisements where legally permitted and consented to;
  • Display contextual or non-personalized advertisements;
  • Measure advertising performance;
  • Produce analytics and reports;
  • Prevent fraud and abuse; and
  • Comply with legal obligations.

Where required, the app presents a Google consent or privacy-choice form before requesting advertisements. Users may change available advertising choices through Google’s privacy controls or the privacy options made available in the app.

Android users may also reset or delete their advertising ID through Android settings.

Google AdMob retains user-activity reporting data for up to 90 days. Certain advertising, cohort, privacy, and aggregated reporting information may be retained for up to 2,555 days, or approximately seven years.

Users who purchase an ad-free Android product do not receive in-app advertisements. Other services described in this policy, such as analytics, crash reporting, purchase processing, AI processing, and security services, may continue to operate.

1.8 Google Play Age Signals on Android

In regions where legally applicable, the Android version may access information supplied through the Google Play Age Signals API.

Depending on the user and jurisdiction, this information may include:

  • A general age range;
  • Age-verification status;
  • Supervision or parental-approval status;
  • The date of a relevant parental approval; and
  • A Play-generated installation identifier.

Age Signals information may be used only to comply with applicable legal and regulatory requirements and to provide age-appropriate treatment.

Jojo Apps does not use Age Signals information for:

  • Advertising or marketing;
  • Personalized advertising;
  • Analytics;
  • User profiling;
  • Business intelligence; or
  • Sale or disclosure to third parties, except where required by law.

Jojo Apps does not retain Age Signals information after it is no longer necessary for the applicable compliance purpose.

1.9 Android purchases

Android subscriptions and one-time purchases are processed by Google Play.

Google Play may provide the app with:

  • Product identifiers;
  • Purchase and subscription status;
  • Purchase tokens;
  • Transaction information; and
  • Information required to acknowledge a purchase and provide paid features.

Jojo Apps does not receive or store complete payment-card details.

Google independently processes and retains purchase and payment information under the Google Privacy Policy and Google Play terms.

1.10 iOS purchases and RevenueCat

Purchases and subscriptions on iOS are processed through Apple’s App Store and RevenueCat.

RevenueCat may receive:

  • An anonymous app user identifier;
  • Product identifiers;
  • Purchase and subscription history;
  • Transaction identifiers and dates;
  • Subscription and entitlement status;
  • Store, country, currency, and pricing information;
  • Whether a purchase was received through Apple Family Sharing; and
  • Information needed to validate purchases, restore purchases, and prevent fraud.

We use this information to:

  • Provide paid features;
  • Determine whether a subscription is active;
  • Restore previous purchases;
  • Manage purchase entitlements;
  • Prevent purchase fraud;
  • Provide purchase support; and
  • Understand subscription performance.

Jojo Apps and RevenueCat do not receive complete payment-card details from Apple.

1.11 Apple Family Sharing

Eligible iOS subscriptions or purchases may be shared through Apple Family Sharing.

Family Sharing shares access to an eligible purchase or subscription. It does not share meal photographs, scan history, food results, or nutritional information with family members.

Apple provides each entitled family member with separate transaction or receipt information. RevenueCat may record whether an entitlement was received through Family Sharing.

Apple does not provide Jojo Apps or RevenueCat with information that allows us to identify or link all members of a particular family group.

Users control Family Sharing through their Apple account and device settings.

1.12 Contact requests

If you submit the contact form on our website, we may receive:

  • Your name;
  • Your email address;
  • The contents of your message;
  • The app and platform concerned; and
  • Any additional information you voluntarily provide.

We use this information to answer questions, provide support, handle privacy requests, and maintain an appropriate record of our response.

Please do not include meal photographs, payment-card information, passwords, or other unnecessary sensitive information in the contact form.

Contact and support correspondence is normally retained for no longer than 24 months after the request is resolved, unless a longer period is required for legal, security, accounting, or dispute-resolution purposes.

2. How we use information

We process information for the following purposes:

  • To provide meal-photo analysis;
  • To save and display meal history on the device;
  • To provide subscriptions and paid features;
  • To display and measure advertising on Android;
  • To understand app usage;
  • To diagnose crashes and technical problems;
  • To protect the app and AI service from fraud and abuse;
  • To provide customer support;
  • To respond to privacy and deletion requests;
  • To comply with legal and regulatory requirements; and
  • To establish, exercise, or defend legal claims.

We do not sell meal photographs or meal-scan history.

3. Legal bases for processing

Where the European Economic Area, United Kingdom, or similar privacy laws apply, we rely on one or more of the following legal bases:

Performance of a service

We process a photograph when you request a meal scan because this processing is necessary to provide the feature you selected.

Consent

We rely on consent where required for personalized advertising, device storage or identifiers, or other legally regulated processing.

Where available, consent may be withdrawn through the app’s privacy controls or the applicable device or platform settings. Withdrawal does not affect processing that occurred before consent was withdrawn.

Legitimate interests

We may process limited analytics, diagnostics, security, and support information for our legitimate interests in:

  • Maintaining and improving the app;
  • Understanding app performance;
  • Preventing fraud and abuse;
  • Protecting users and our services; and
  • Responding to support requests.

We rely on legitimate interests only where those interests are not overridden by the user’s rights and interests.

Legal obligations

We may process or retain information when necessary to comply with purchase, tax, accounting, consumer-protection, age-appropriate-treatment, regulatory, or other legal obligations.

4. Service providers and disclosures

We use the following providers:

  • Google Firebase AI Logic and Google Cloud Vertex AI for meal-image processing;
  • Google Analytics for Firebase for app analytics;
  • Firebase Crashlytics for crash reporting;
  • Firebase App Check, Google Play Integrity, and Apple App Attest for security;
  • Google AdMob and the Google User Messaging Platform for Android advertising and privacy choices;
  • Google Play Billing for Android purchases;
  • Apple App Store and StoreKit for iOS purchases and Family Sharing;
  • RevenueCat for iOS purchase and entitlement management; and
  • JouwWeb/Webador and related website providers for website hosting and contact-form delivery.

These providers may process information on our behalf or as independent controllers, depending on the service and context.

We may also disclose information:

  • When required by law or a valid legal request;
  • To investigate fraud, abuse, or security incidents;
  • To protect the rights or safety of users, Jojo Apps, or others;
  • To professional advisers subject to confidentiality obligations; or
  • In connection with a merger, acquisition, restructuring, or transfer of the app, with appropriate notice and safeguards.

Information about Google’s privacy practices is available at:

https://policies.google.com/privacy

Information about Firebase privacy and retention is available at:

https://firebase.google.com/support/privacy

Information about RevenueCat’s privacy practices is available at:

https://www.revenuecat.com/privacy-policy

Information about Apple’s privacy practices is available at:

https://www.apple.com/legal/privacy/

5. Data retention

We use the following general retention periods:

  • Meal photographs and scan history stored on the device: Until deleted by the user, cleared through device settings, or removed by uninstalling the app, subject to device backups.
  • Firebase AI Logic: Firebase AI Logic itself does not store the submitted content.
  • Vertex AI temporary processing: Input and output data may be cached in memory for up to 24 hours.
  • Vertex AI abuse monitoring: Requests identified as potentially abusive may be logged for up to 30 days.
  • Firebase AI monitoring logs: Normally up to 30 days if monitoring is enabled, unless another period is configured.
  • Firebase Analytics: User-level and event-level information for no longer than 14 months; aggregated reports may remain longer.
  • Firebase Crashlytics: Normally 90 days.
  • Firebase App Check: Tokens for no longer than seven days, or up to 30 days when replay protection applies.
  • AdMob user-activity reports: Up to 90 days.
  • Certain AdMob aggregated and advertising reports: Up to 2,555 days, or approximately seven years.
  • Purchase and entitlement records: For as long as necessary to provide purchases, restore entitlements, prevent fraud, handle disputes, and satisfy accounting or legal obligations.
  • Contact and support requests: Normally up to 24 months after resolution.

We may retain aggregated or irreversibly anonymized information for longer because it no longer identifies a user or device.

6. Data deletion

AI Meal Scanner does not provide Jojo Apps user accounts.

Deleting locally stored meal data

Users can delete individual meal scans using the delete control displayed beside a scan.

Users may also delete local app data through the application settings provided by Android or iOS.

Uninstalling AI Meal Scanner removes its active local app storage. Copies may remain temporarily in a device backup controlled by Google, Apple, or the device manufacturer until the backup is replaced or deleted.

Requesting deletion

To request deletion of information that Jojo Apps or our service providers can identify and control, submit the contact form at:

https://www.jojo-apps.com/contact

Use “AI Meal Scanner data deletion request” as the subject or include that phrase at the beginning of the message.

Please include:

  • Whether you use Android or iOS;
  • A general description of the information you want deleted; and
  • Any information reasonably needed to locate the relevant support or purchase record.

Do not include passwords or complete payment-card information.

We will normally acknowledge and complete a valid request within 30 days. We may request additional information when reasonably necessary to verify the request or locate the relevant information.

Some analytics, advertising, security, and crash information is associated only with pseudonymous device or installation identifiers. We may be unable to identify that information using a name or email address submitted through the contact form. Information that cannot reasonably be linked to a deletion request will be removed according to the retention periods described in this policy.

Apple and Google independently retain purchase and payment records. Requests concerning records controlled by Apple or Google must be submitted through the privacy controls associated with the relevant Apple or Google account.

7. Your privacy rights

Depending on where you live, you may have the right to:

  • Request access to personal data;
  • Request correction of inaccurate data;
  • Request deletion of personal data;
  • Request restriction of processing;
  • Object to certain processing;
  • Receive certain data in a portable format;
  • Withdraw consent;
  • Appeal a decision concerning a privacy request; and
  • Submit a complaint to a data-protection authority.

To exercise an applicable right, use the contact form at:

https://www.jojo-apps.com/contact

Users in Belgium may submit a complaint to the Belgian Data Protection Authority:

https://www.dataprotectionauthority.be/

8. Advertising choices

Android users may be shown a Google privacy or consent message where required.

Available advertising choices may include:

  • Accepting or refusing personalized advertising;
  • Managing advertising partners;
  • Revisiting privacy options in the app;
  • Resetting or deleting the Android advertising ID; and
  • Managing advertising personalization through Google account or Android settings.

Refusing personalized advertising does not necessarily prevent all advertisements. The app may instead display contextual or non-personalized advertisements using limited information.

9. Security

We use commercially reasonable technical and organizational safeguards, including:

  • Encrypted network connections;
  • Platform-provided application storage;
  • Firebase App Check;
  • Google Play Integrity;
  • Apple App Attest;
  • Restricted access to service dashboards; and
  • Data-minimization and retention practices.

No electronic transmission or storage system is completely secure. We cannot guarantee absolute security.

10. International processing

Our service providers may process information in countries other than the country where the user lives.

Where required, international transfers are protected through appropriate legal mechanisms, such as adequacy decisions, contractual safeguards, or other transfer mechanisms recognized by applicable law.

11. Children

AI Meal Scanner is not directed to children under 13, and we do not knowingly request personal information from children under 13.

Age and parental-consent requirements vary by country and region. Where legally required, the app may use platform-provided age and parental-approval signals solely to provide legally compliant and age-appropriate treatment.

If you believe that a child has provided personal information through the app or website, submit the contact form at:

https://www.jojo-apps.com/contact

We will investigate and delete the information where appropriate.

12. Third-party links

The app or website may contain links to services that are not operated by Jojo Apps.

We are not responsible for the content or privacy practices of third-party websites or services. Users should review the privacy policy of a third-party service before providing information to it.

13. Privacy-policy website

The website hosting this Privacy Policy may process:

  • IP address;
  • Browser and device information;
  • Cookie or consent choices;
  • Page views and interactions; and
  • Information submitted through the contact form.

The website may use services provided by JouwWeb/Webador, Google Analytics, Google Ads, and Plausible or similar website analytics providers.

Website processing is separate from meal scanning performed by the mobile app.

14. Changes to this Privacy Policy

We may update this Privacy Policy when:

  • App functionality changes;
  • We add or remove a service provider;
  • Our data practices change;
  • Retention periods change; or
  • Legal or regulatory requirements change.

The effective date at the top identifies the latest version. Material changes may be communicated through the app or website where appropriate.

15. Contact

For privacy questions, support requests, or deletion requests, use:

https://www.jojo-apps.com/contact

You may also contact:

Jojo Apps
Ganzenberg 63
9220 Moerzeke
Belgium

Email: support@jojoapps-company.com